Legal Center

Privacy Policy

Effective Date: January 20, 2026

1. Introduction

Welcome to AgentShield ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the sovereignty of your data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI observability and governance platform.

2. Data Sovereignty and Regional Processing

Data Residency Core Feature

During registration, you selected a specific data region (e.g., European Union or United States).

If you selected "European Union" (EU): Your data is processed and stored on servers located within the EU. We apply strict GDPR standards and prevent data egress to non-adequate jurisdictions unless explicitly authorized by you via specific AI model selection (e.g., choosing a US-only model).

If you selected "United States" (US): Your data is processed on servers located in the US, compliant with NIST AI RMF and local regulations.

3. Information We Collect

A. Personal Data (Account Information)

  • Email address, encrypted password, and billing details (handled by our payment processor, Stripe).
  • Login metadata (IP address, user agent) for security and fraud prevention.

B. AI Traffic Data (The "Payload")

  • Prompts and Completions: We process the text you send to AI models to provide observability, cost tracking, and PII masking.
  • PII Masking: If you enable our "PII Guard" feature, sensitive data (names, credit cards) is redacted before leaving our infrastructure.
  • Transient Processing: Unless you enable "Full Logging/Auditing," payload data is processed in-memory for arbitration and metrics calculation and is not permanently stored.

4. How We Use Your Information

We use your data to:

  • Route API requests to your chosen Upstream Providers (e.g., OpenAI, Anthropic).
  • Calculate usage costs and optimize model selection (Arbitrage).
  • Detect and block malicious prompts (Security).
  • Comply with legal obligations based on your selected jurisdiction.
We DO NOT use your customer data to train our own AI models.

5. Sharing with Third Parties (Sub-processors)

To provide the Service, we must share data with:

  • Upstream AI Providers: (e.g., OpenAI, Google, Anthropic). You acknowledge that by using a specific model, you authorize us to send your prompt to that provider.
  • Infrastructure Providers: Supabase / AWS / Render (Regions strict per your selection).
  • Resend: For transactional emails.
  • Stripe: For payment processing.
Regional Compliance

6. GDPR Compliance (EU)

Legal Basis: Performance of Contract and Legitimate Interests. You have the right to access, rectify, delete ("Right to be Forgotten"), and export your data.

7. CCPA/CPRA (US)

We do not "sell" your personal information. You have the right to know what personal information we collect and to request deletion.

8. Data Retention

We retain account data for as long as your account is active. AI traffic logs (if enabled) are retained according to your configured retention policy (default: 30 days) and then automatically deleted.

9. Security

We implement industry-standard security measures, including encryption in transit TLS 1.3 and at rest AES-256. However, no method of transmission over the Internet is 100% secure.

10. Changes to This Policy

We may update this policy to reflect changes in law or our technology. We will notify you of significant changes via email or a dashboard alert.

11. Contact Us

For privacy inquiries or to exercise your rights, contact our Data Protection Officer (DPO) at:

privacy@getagentshield.com